Repository navigation
Fix timeout overflow and IOCP rounding; validate timer arithmetic and heap invariants - #110
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Mathematical review of master 5f5027c after #109 found two reproducible numerical edge cases:
Use fallible, saturating conversion for positive finite executor timeouts, preserving completion and cancellation. Round finite IOCP waits up to milliseconds and cap below INFINITE. Existing ordinary timeout behavior, public signatures and dependencies remain unchanged.
The integer IOCP rule is m = min(ceil(n / 1,000,000), 2**32 - 2). Before saturation its quantization error is nonnegative and strictly below 1 ms; this is not a bound on OS wake latency. Microsoft documents zero as an immediate timeout. The conversion remains allocation-free and constant-time; Windows CPU/latency performance was not measured locally.
Validation additions:
Executed on Linux x86_64 / CPython 3.14.7 / Rust nightly-2026-09-25:
Full local suites are not green because of those restrictions. Windows/macOS, free-threaded Python and working io_uring were not executed locally. IOCP scalar arithmetic is tested on Linux under the existing test configuration. These bounded model tests are not a formal proof; generation wraparound is outside their scope.
See docs/math-validation.md for the requirement-to-test matrix, numerical risk ledger, derivation, reproducible seeds and verification limits.
CI follow-up (
1bd0132): the initial Linux / Python 3.15t job exposed a stream-connection race:fast_open_connection_resultborrowed the protocol on a smol worker while loop callbacks held a mutable borrow. Reproduced locally with Python 3.15.0rc3 free-threaded and the GIL disabled. Result assembly now follows a direct Python await on the loop thread, which also propagates cancellation tocreate_connectioninstead of abandoning its inner task. Added immediate-peer-close stress, thread/loop/context affinity, connection error and cancellation tests. Fixed free-threaded build: 12,800 stress connections passed; full suite 416 passed, 2 Unix-socket EPERM failures, 68 skips. CPython 3.14 release suite: 481 passed, 2 Unix-socket EPERM failures, 3 skips. Clippy all targets/all features, focused Pyright, Ruff, formatting, MkDocs and hotpath audit pass. On that commit, Linux / Python 3.15t passed in GitHub CI (418 tests, 68 skips); earlier local limitations above describe the initial mathematical review, before this free-threaded follow-up.STARTTLS fixture follow-up (
ba346a8): Windows CPython 3.11.9 intermittently failed in the stdlib ProactorEventLoop comparison after the client handshake completed and the server stayed pending. Explicit start events and pausing baseline plaintext reads prevent the separate early-ClientHello buffering race (cf. python/cpython#142352), but did not eliminate the Proactor failure. A diagnostic run with a longer deadline passed in under 0.19 s; that is not evidence that the original 3-second deadline was too short. The final comparison explicitly uses asyncio.SelectorEventLoop consistently across platforms, alongside uvloop where available and native rsloop. Original deadlines are restored and temporary tracing is removed. This does not fix or verify stdlib Proactor STARTTLS; Windows rsloop/IOCP STARTTLS remains covered in both upgrade orders. The runner now reports the ten slowest tests. Local final TLS/tooling validation: 128 passed, one existing Unix-socket EPERM failure; Ruff and focused Pyright pass. Tooling alone: 98 passed. Final-head CI (ba346a8): Tests run 38042522678 passed all 38 jobs, including Rust default/all-features, Clippy, Miri, hotpath/tooling and Linux/macOS/Windows Python matrices. Windows/Python 3.11: 395 passed, 91 skipped, 98 deselected. Linux/Python 3.15t passed. MkDocs also passed. Windows/macOS results are from GitHub Actions, not local execution.